PT-2019-16717 · Cloud Foundry · Cloud Foundry Uaa

Kristian Kraljic

·

Published

2019-06-19

·

Updated

2020-02-10

·

CVE-2019-3787

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry UAA versions prior to 73.0.0
Description The issue allows for potential account takeover through password recovery emails sent to a potentially fraudulent address. When a user's email address is not provided and the username does not contain an @ character, the system appends "unknown.org" to the email address. Since "unknown.org" is held by a private company, this creates an attack vector.
Recommendations For versions prior to 73.0.0, update to version 73.0.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3787

Affected Products

Cloud Foundry Uaa